CIO Brief: Managed Threat Detection — Build vs. Buy for AWS
Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.
The short version: Amazon GuardDuty, launched in 2017, watches your AWS accounts for signs of attack and costs relatively little. The decision is not really build versus buy — it is whether you have someone to act on what it finds.
What managed detection gives you
Services like GuardDuty and Microsoft Defender for Cloud detect common attack patterns automatically: stolen credentials, compromised servers, crypto mining, unusual data access. Building comparable detection in-house would require log pipelines, a SIEM, threat intelligence and specialist staff.
Where companies go wrong
- Turning it on in some accounts or regions but not all.
- Generating alerts that go to an inbox nobody checks.
- Assuming detection is the same as response.
Questions to ask your team
- Is threat detection enabled in every AWS account and region we use?
- Who receives high-severity alerts, and how fast do they respond — including nights and weekends?
- What was the last real finding, and what did we do about it?
- Would a managed detection and response provider be more reliable than our current coverage?
What good looks like
Detection everywhere, alerts routed to a responsible person or provider with defined response times, and a monthly summary of findings and actions to leadership.
The decision
The tools are inexpensive; the people are not. If you lack 24/7 coverage, budget for a managed detection and response service or a retainer that monitors these alerts for you.
- Amazon GuardDuty Launches at re:Invent 2017: Managed Threat Detection for AWS Platform Changes
- How to Enable GuardDuty Across an AWS Organization in One Afternoon How-To & Hardening
- GuardDuty Finding Triage Runbook for Small Security Teams How-To & Hardening